First published: Mon Apr 27 2020(Updated: )
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11941 is a vulnerability in Open-AudIT 3.2.2 that allows OS command injection in the Discovery module.
CVE-2020-11941 has a severity rating of 8.8, which is considered high.
Open-AudIT version 3.2.2 is affected by CVE-2020-11941.
To fix CVE-2020-11941, update Open-AudIT to version 3.3.0 or newer.
Yes, you can refer to the following links for more information: 1. [Packet Storm Security Advisory](http://packetstormsecurity.com/files/157476/Open-AudIT-3.2.2-Command-Injection-SQL-Injection.html) 2. [Open-AudIT Release Notes for v3.3.0](https://community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.0) 3. [Core Security Advisories](https://www.coresecurity.com/advisories/open-audit-multiple-vulnerabilities)